2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-39376MEDIUM6.5 SiberianCMS - CWE-284 Improper Access Control Authorized user may disable a security feature over the network
CVE-2023-39375CRITICAL9.8 SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges
CVE-2023-39347CRITICAL9Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An attacker with the ability ...
CVE-2023-39233MEDIUM6.5The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may disclos...
CVE-2023-38615HIGH7.8The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14. An app may be able to exe...
CVE-2023-38596MEDIUM5.5The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watch...
CVE-2023-38586CRITICAL10An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed ...
CVE-2023-37448LOW3.3A lock screen issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14. A user may be ...
CVE-2023-36851MEDIUM5.3A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauth...
CVE-2023-35990LOW3.3The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17, watchOS 10, iOS 16.7 and iPad...
CVE-2023-35984MEDIUM4.3The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS So...
CVE-2023-35793HIGH8.8An issue was discovered in Cassia Access Controller 2.1.1.2303271039. Establishing a web SSH session to gateways is vuln...
CVE-2023-35074HIGH8.8The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and...
CVE-2023-35071CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MRV Tech Logging A...
CVE-2023-34043MEDIUM6.7VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access...
CVE-2023-32541HIGH7.8A use-after-free vulnerability exists in the footerr functionality of Hancom Office 2020 HWord 11.0.0.7520. A specially ...
CVE-2023-32421MEDIUM5.5A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14. An app ...
CVE-2023-32396HIGH7.8This issue was addressed with improved checks. This issue is fixed in Xcode 15, tvOS 17, watchOS 10, iOS 17 and iPadOS 1...
CVE-2023-32377HIGH7.8A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14. An app may ...
CVE-2023-32361MEDIUM5.5The issue was addressed with improved handling of caches. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS ...
CVE-2023-30961MEDIUM6.1Palantir Gotham was found to be vulnerable to a bug where under certain circumstances, the frontend could have applied a...
CVE-2023-30959MEDIUM5.4In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result i...
CVE-2023-30493MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.2....
CVE-2023-30472MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MyThemeShop URL Shortener by MyThemeShop plugin <= 1.0.17 ...
CVE-2023-30471MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cornel Raiu WP Search Analytics plugin <= 1.4.7 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now